ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Serious MacOS Vulnerability Patched

mediumVulnerabilityimportance 30
Full article151 words · extracted from schneier.com · click to collapse

Apple just patched a MacOS vulnerability that bypassed malware checks.

The flaw is akin to a front entrance that’s barred and bolted effectively, but with a cat door at the bottom that you can easily toss a bomb through. Apple mistakenly assumed that applications will always have certain specific attributes. Owens discovered that if he made an application that was really just a script—code that tells another program what do rather than doing it itself—and didn’t include a standard application metadata file called “info.plist,” he could silently run the app on any Mac. The operating system wouldn’t even give its most basic prompt: “This is an application downloaded from the Internet. Are you sure you want to open it?”

More.

Tags: Apple, malware, operating systems, patching, vulnerabilities

Posted on April 30, 2021 at 7:38 AM7 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/04/serous-macos-vulnerability-patched.html